Insecure Direct Object Reference in Frontend User Notes Plugin for WordPress
CVE-2025-12071
4.3MEDIUM
What is CVE-2025-12071?
The Frontend User Notes plugin for WordPress has a vulnerability that permits authenticated attackers with Subscriber-level access and higher to exploit the 'funp_ajax_modify_notes' AJAX endpoint. Due to a lack of necessary validation on user-controlled keys, attackers can alter notes that belong to other users, compromising user data and privacy. All versions up to and including 2.1.0 are affected, underscoring the urgency for users to update to safer versions.
Affected Version(s)
Frontend User Notes 0 <= 2.1.0